Director of Cybersecurity - GRC
PSEGAbout the role
Job Summary
The Director, Cybersecurity Governance, Risk, and Compliance leads the development, implementation, and ongoing coordination of enterprise-wide Cybersecurity Governance, Risk, and Compliance, including Regulatory Assurance (e.g. NRC, SOX, DoE, NERC CIP, TSA, Internal Audits, etc.), Cybersecurity Risk, Cybersecurity Policy, Cybersecurity Awareness, and Nth Party Risk Management and Assurance. (S)he coordinates across all business lines, service departments, external risk organizations (e.g. cross-sector cyber industry trade organizations), and peer energy companies. As PSEG’s senior leader responsible for Cybersecurity Governance, Risk, and Compliance, (s)he will also be responsible for defining and aligning cybersecurity policies, strategy, and standards. (S)he will be responsible for multiple discrete projects/enhancements to build, maintain, and mature capabilities, including people, processes, and technologies. (S)he will engage across the entire IT, OT, and managed services landscapes, including leading a team across these environments.
(S)he will spend his/her time
* Serving as the Subject Matter Expert for Cybersecurity governance, risk, and compliance issues/concerns/audits.
* Conducting cybersecurity assessments, identifying risks, and tracking/reporting on remediations.
* Providing cybersecurity insight and expertise in assessing new business opportunities.
* Identifying opportunities for process improvements to deliver increasing efficiency within the Risk and Control framework.
* Interacting with auditors on cybersecurity management oversight.
* Coordinating with outside vendors/third-parties to protect client information, to secure data transmission protocols, and to complete/remediate Information/cybersecurity assessments.
* Collaborating closely with developers and infrastructure teams to implement the Cybersecurity policies required to protect the integrity, confidentiality, and availability of the information on an end-to-end basis.
* Implementing the risk assessment framework, which identifies critical cybersecurity and privacy impacting business process and/or systems.
* Maintaining the global Cybersecurity and IT risk registers, tracking remediations, and creating status reports/metrics.
* Completing risk assessments of new/existing infrastructure, systems, Industrial Control Systems, and other components.
* Conducting risk assessments of third-party vendors to evaluate cybersecurity controls for protecting company-specific data.
* Leading and/or contributing to the creation and maintenance of the enterprise’s cybersecurity documents (policies, standards, guidelines and procedures). Ensuring enforcement of these enterprise cybersecurity documents.
* Preparing for, supporting, and potentially presenting at, Cybersecurity Council, Senior Executive Team, and Board of Directors meetings.
* Preparing senior-level technical reports for executive management.
* Providing support and risk guidance for enterprise infrastructure, the wireless environment, Cloud software/infrastructure security, secure software development, and data protection.
* Collaborating closely with Digital Workplace, Infrastructure, Enterprise Resource Planning, and Application Development Teams to identify and remediate cybersecurity issues.
* Identifying/overseeing remediation of open cybersecurity issues and validating closure.
* Maintaining up-to-date cybersecurity knowledge, including awareness of innovative solutions/processes, emerging standards, and new threat vectors by reading professional publications, maintaining personal networks, and participating in professional organizations.
Job Responsibilities
- Directs, coaches, and counsels internal/external cyber resources on Cybersecurity technologies, including Regulatory Assurance (e.g. NRC, SOX, DoE, NERC CIP, TSA, Internal Audits, etc.), Cybersecurity Risk, Cybersecurity Policy, Cybersecurity Awareness, and Nth Party Risk Management and Assurance for all lines of business and service departments for both IT and OT landscapes. Ensure that Cybersecurity Governance, Risk, and Compliance service delivery aligns with the corporate IT strategy, including development of Cybersecurity operations standards, capacity planning, lifecycle management plans, solution selection, and partner management. Ensure scalability of Cybersecurity Governance, Risk, and Compliance capabilities, including hardware and software, to meet business needs and risk tolerances.
- Develops and implements best practices for PSEG Cybersecurity Governance, Risk, and Compliance capabilities. Participate in external risk organizations (including with peer groups) to learn from other organizations and to benchmark our program. Partner with professional Cybersecurity Governance, Risk, and Compliance associations, service providers, and to identify and implem
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s